CVE Feed

    Dashboard / CVE / CVE-2023-45133

    CVE-2023-45133

    Babel is a compiler for writingJavaScript. In `@babel/traverse` prior to versions 7.23.2 and 8.0.0-alpha.4 and all versions of `babel-traverse`, using Babel to compile code that was specifically crafted by an attacker can lead to arbitrary code execution during compilation, when using plugins that rely on the `path.evaluate()`or `path.evaluateTruthy()` internal Babel methods. Known affected plugins are `@babel/plugin-transform-runtime`; `@babel/preset-env` when using its `useBuiltIns` option; and any "polyfill provider" plugin that depends on `@babel/helper-define-polyfill-provider`, such as `babel-plugin-polyfill-corejs3`, `babel-plugin-polyfill-corejs2`, `babel-plugin-polyfill-es-shims`, `babel-plugin-polyfill-regenerator`. No other plugins under the `@babel/` namespace are impacted, but third-party plugins might be. Users that only compile trusted code are not impacted. The vulnerability has been fixed in `@babel/[email protected]` and `@babel/[email protected]`. Those who cannot upgrade `@babel/traverse` and are using one of the affected packages mentioned above should upgrade them to their latest version to avoid triggering the vulnerable code path in affected `@babel/traverse` versions: `@babel/plugin-transform-runtime` v7.23.2, `@babel/preset-env` v7.23.2, `@babel/helper-define-polyfill-provider` v0.4.3, `babel-plugin-polyfill-corejs2` v0.4.6, `babel-plugin-polyfill-corejs3` v0.8.5, `babel-plugin-polyfill-es-shims` v0.10.0, `babel-plugin-polyfill-regenerator` v0.5.3.

    Published:Oct 11, 2023
    Last Modified:Feb 13, 2025
    EPS:Oct 12, 2023
    EPSS Score:0.00067
    CVSS Score:9.4

    Affected Products

    Vendor
    Babeljs
    Product
    Babel
    Vendor
    Babeljs
    Product
    Babel-helper-define-polyfill-provider
    Vendor
    Babeljs
    Product
    Babel-plugin-polyfill-corejs2
    Vendor
    Babeljs
    Product
    Babel-plugin-polyfill-corejs3
    Vendor
    Babeljs
    Product
    Babel-plugin-polyfill-es-shims
    Vendor
    Babeljs
    Product
    Babel-plugin-polyfill-regenerator
    Vendor
    Babeljs
    Product
    Babel-plugin-transform-runtime
    Vendor
    Babeljs
    Product
    Babel-preset-env
    Vendor
    Debian
    Product
    Debian Linux

    Exploits

    No exploit reference

    Common Attack Pattern Enumeration and Classification (CAPEC)

    References

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High